CVE-2026-64356 PUBLISHED

xfs: fix memory leak in xfs_dqinode_metadir_create()

Assigner: Linux
Reserved: 19.07.2026 Published: 25.07.2026 Updated: 25.07.2026

In the Linux kernel, the following vulnerability has been resolved:

xfs: fix memory leak in xfs_dqinode_metadir_create()

If xfs_metadir_create() fails in xfs_dqinode_metadir_create(), the current code returns directly, leaking the allocated update and transaction state. If the subsequent commit fails, the caller-owned inode reference is left behind.

Fix this memory leak by routing the create failure path through xfs_metadir_cancel(). For both create and commit failures, finish and release any inode returned to the caller, mirroring the unwind pattern in xfs_metadir_mkdir().

The bug was first flagged by an experimental analysis tool we are developing for kernel memory-management bugs while analyzing v6.13-rc1. The tool is still under development and is not yet publicly available. Manual inspection confirms that the bug is still present in v7.1.1.

An x86_64 allyesconfig build showed no new warnings. Runtime validation used kprobe fault injection during mount -o uquota on a metadir XFS image. Injecting xfs_metadir_create() reproduced the old active-update path that left mount stuck later in mount setup; after this change, the same injection reported cancel_hits=1 and irele_hits=1. Injecting xfs_metadir_commit() exercised the old inode-reference leak path; after this change, it reported irele_hits=1.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from e80fbe1ad8eff7d7d1363e14f1e493d84dd37c84 to c3d3d2212c2966973dd7d603c6c6e6ed6fc7fbe1 (excl.)
  • affected from e80fbe1ad8eff7d7d1363e14f1e493d84dd37c84 to 06a2e6dbaa26c0740ac76dfa66b0aedc78d05820 (excl.)
  • affected from e80fbe1ad8eff7d7d1363e14f1e493d84dd37c84 to 45de375b25060edf46e20abb36521ba530336ceb (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 6.13 is affected
  • unaffected from 0 to 6.13 (excl.)
  • unaffected from 6.18.39 to 6.18.* (incl.)
  • unaffected from 7.1.4 to 7.1.* (incl.)
  • unaffected from 7.2-rc2 to * (incl.)

References